Skip to main content

How ISO 27001 implementation works

By Harry Sidhu — Director and Principal Consultant, Aegentra · Updated

ISO 27001 implementation turns business context, information-security risk and operating responsibilities into a management system that can be evidenced and improved. The sequence normally covers scope, risk assessment, the Statement of Applicability, implementation of risk-selected controls, operating evidence, internal audit, management review, corrective action and certification-body handover. The exact timeline depends on scope, maturity, access, remediation and management availability.

The implementation sequence

  1. Define context and scope. Confirm the organisational boundary, interested parties, applicable requirements, information and systems that the ISMS will govern.
  2. Assess information-security risk. Use an agreed, repeatable method to identify, analyse and evaluate risks, assign owners and decide treatment.
  3. Create the Statement of Applicability. Record necessary controls, compare them with Annex A, justify applicability decisions and track implementation status.
  4. Implement and operate controls. Assign responsibilities, create necessary documented information and operate the risk-selected organisational, people, physical and technological controls.
  5. Retain objective evidence. Keep records showing that processes and controls operate as intended, including decisions, approvals, reviews, tests and corrective actions.
  6. Complete internal audit and management review. Use a competent auditor who can protect objectivity and impartiality, report findings to management and complete the required management review.
  7. Correct and hand over. Address relevant corrective actions and prepare the evidence trail for an independent accredited certification body’s Stage 1 and Stage 2 assessments.

How controls are selected

Applicable Annex A controls are selected through the organisation’s risk assessment and recorded in the Statement of Applicability. Aegentra implements the management-system requirements and risk-selected controls agreed in scope; it does not treat all 93 Annex A controls as a universal implementation checklist.

Risks come first; Annex A is the cross-check, not the starting point.

Operating evidence, not a document binder

Where Aeges is included, it can collect or reproduce supported Microsoft 365 technical evidence and help maintain traceability to risks, controls and owners. It does not evidence every Annex A control and it does not replace policies, management decisions, people records, supplier evidence, physical-security evidence, interviews, internal audit or professional judgement.

Internal audit and management review

A competent internal employee or an external auditor can perform an ISO 27001 internal audit if the organisation protects objectivity and impartiality. The auditor should have competence relevant to the audit scope and should not audit work they designed, implemented or operate. When a small team cannot avoid self-review, a separately appointed external auditor usually provides the clearest separation.

Implementation, internal audit and certification are separate responsibilities. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. An independent accredited certification body performs Stage 1 and Stage 2 and makes the certification decision.

Where a separately appointed external auditor is appropriate, review Aegentra’s independent ISO 27001 internal-audit service.

Timeline and dependencies

Aegentra may target an approximately 12-week implementation programme for an appropriately scoped, Microsoft 365-first organisation with sufficient leadership availability and no major remediation blockers. This is a planning assumption, not a guarantee. Timing depends on the ISMS boundary, starting maturity, technical complexity, evidence availability, client decisions, remediation, internal-audit arrangements and the certification body’s schedule. The written proposal records the actual delivery plan and dependencies.

Implementation and certification costs

Implementation and certification are separate costs. Aegentra confirms its implementation fee after discovery. The certification body quotes Stage 1, Stage 2 and ongoing surveillance separately based on the certified scope, headcount, sites and audit duration. Obtain current written quotations rather than relying on a universal market range.

Build the complete budget with the ISO 27001 certification cost guide, including implementation, independent audit, remediation and ongoing ownership.

Certification-body handover

The organisation retains ownership of the ISMS and evidence. Aegentra can organise the agreed handover and support clarification, while the certification body controls its audit plan, findings and certification decision.

Frequently asked questions

How long does ISO 27001 implementation take?

Aegentra may target an approximately 12-week implementation programme for an appropriately scoped, Microsoft 365-first organisation with sufficient leadership availability and no major remediation blockers. This is a planning assumption, not a guarantee. Timing depends on the ISMS boundary, starting maturity, technical complexity, evidence availability, client decisions, remediation, internal-audit arrangements and the certification body’s schedule. The written proposal records the actual delivery plan and dependencies.

Do we need to implement all 93 Annex A controls?

Applicable Annex A controls are selected through the organisation’s risk assessment and recorded in the Statement of Applicability. Aegentra implements the management-system requirements and risk-selected controls agreed in scope; it does not treat all 93 Annex A controls as a universal implementation checklist.

Who can perform the internal audit?

A competent internal employee or an external auditor can perform an ISO 27001 internal audit if the organisation protects objectivity and impartiality. The auditor should have competence relevant to the audit scope and should not audit work they designed, implemented or operate. When a small team cannot avoid self-review, a separately appointed external auditor usually provides the clearest separation.

Can Aegentra implement and audit the same ISMS?

The person conducting the audit should not audit their own work. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. The service is also available for systems implemented in-house or by another provider, subject to the same scope, prior-involvement and conflict checks.

Does Aegentra issue ISO 27001 certification?

No. Aegentra can support implementation and readiness, but an independent accredited certification body performs Stage 1 and Stage 2 and makes the certification decision.

Who is accountable for an ISO 27001 implementation engagement?

An implementation plan should identify the accountable lead, the client owners and any technical support required to build and operate the ISMS.

  • Accountable delivery — ISO 27001 implementation lead. The written scope names the lead and records responsibilities, deliverables and exclusions.
  • Control implementation — Client control owners with specialist support where required. Ownership, access and evidence responsibilities are assigned for the agreed controls.
  • Independent assurance — Separately scoped internal auditor and certification body. Implementation, Clause 9.2 internal audit and certification remain distinct functions.

Qualified delivery matched to your scope

Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.

The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.

Team qualifications and credentials

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Credentials are held across the delivery team and matched to assigned roles. The proposal identifies the consultants, responsibilities and relevant qualification evidence before work begins.

Aegentra confirms the delivery roles for a client engagement in writing; this guide does not imply that one fixed team suits every ISMS. View our delivery-team capability.

Where we work

Teams in Melbourne and Sydney. Delivered across all Australian states and territories, remotely or onsite by arrangement. New Zealand and Asia Pacific by arrangement.